

de Recherche et d’Innovation
en Cybersécurité et Société
Amari, H.; Houda, Z. A. El; Moudoud, H.; Khoukhi, L.; Belguith, L. H.
Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected Vehicles Article d'actes
Dans: M., Valenti; D., Reed; M., Torres (Ed.): IEEE Int Conf Commun, p. 4257–4262, Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 15503607 (ISSN); 979-833150521-9 (ISBN), (Journal Abbreviation: IEEE Int Conf Commun).
Résumé | Liens | BibTeX | Étiquettes: Block-chain, Blockchain, Central layers, Computer crime, Connected vehicle, Connected Vehicles, Cyber threats, Cyberthreat detection, Cyberthreats, Cyberthreats Detection, Data privacy, Federated learning, Intelligent transport, Intelligent vehicle highway systems, Internet of things, Intrusion Detection, Intrusion Detection Systems, Learning systems, Network security, SDN, Threat detection, Traffic control, Vehicles
@inproceedings{amariBlockchainBasedFederatedLearning2025,
title = {Blockchain-Based Federated Learning for Enhanced Cyber-Threats Detection in Connected Vehicles},
author = {H. Amari and Z. A. El Houda and H. Moudoud and L. Khoukhi and L. H. Belguith},
editor = {Valenti M. and Reed D. and Torres M.},
url = {https://www.scopus.com/pages/publications/105018456633?origin=resultslist},
doi = {10.1109/ICC52391.2025.11161266},
isbn = {15503607 (ISSN); 979-833150521-9 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {IEEE Int Conf Commun},
pages = {4257–4262},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Over the past few years, there have been made significant strides in advancing the Internet of Vehicles (IoV), recognizing its strategic importance in Intelligent Transport Systems. The proliferation of connected and autonomous vehicles on the roads has propelled the IoV into the spotlight. However, addressing the specific demands of vehicular networks, such as low latency, high mobility, extensive connectivity of 5G/6G networks, and robust security, remains a substantial challenge. Therefore, there is a critical need for substantial progress in implementing a resilient Intrusion Detection System within the IoV ecosystem. This paper introduces VFed-IDS, a decentralized, secure, flexible, scalable, and robust Blockchain and Federated Learning-based intrusion detection system. VFed-IDS is designed to identify cyber threats in the IoV while preserving privacy in connected vehicles. The proposed architecture consists of three main layers: the central layer, the local layer, and the Blockchain layer. The central layer includes the SDN Controller, responsible for training and aggregating the global model. The local layer comprises vehicles training individual models based on their private local datasets. The Blockchain layer introduces the Smart Contract VFed-SC, which manages the list of authenticated and collaborating vehicles in the Federated Learning process. It also hashes trained local model updates before transmitting them as transactions between the central and local layers. Simulation results demonstrate that VFed-IDS achieves a high accuracy rate of 99%, effectively enhancing the autonomous behavior of connected vehicles against cyber threats. © 2025 IEEE.},
note = {Journal Abbreviation: IEEE Int Conf Commun},
keywords = {Block-chain, Blockchain, Central layers, Computer crime, Connected vehicle, Connected Vehicles, Cyber threats, Cyberthreat detection, Cyberthreats, Cyberthreats Detection, Data privacy, Federated learning, Intelligent transport, Intelligent vehicle highway systems, Internet of things, Intrusion Detection, Intrusion Detection Systems, Learning systems, Network security, SDN, Threat detection, Traffic control, Vehicles},
pubstate = {published},
tppubtype = {inproceedings}
}
Merzouki, K.; Hadi, Y.; Elghazi, H.; Moudoud, H.; Houda, Z. A. El
Graph Neural Network Framework for Advanced Persistent Threat Detection in IIoT Environments Article d'actes
Dans: F., El Bouanani; F., Ayoub (Ed.): Int. Conf. Adv. Commun. Technol. Netw., CommNet - Proc., Institute of Electrical and Electronics Engineers Inc., 2025, ISBN: 979-833155781-2 (ISBN), (Journal Abbreviation: Int. Conf. Adv. Commun. Technol. Netw., CommNet - Proc.).
Résumé | Liens | BibTeX | Étiquettes: Advanced persistent threat, Advanced Persistent Threats, Anomaly detection, CICAPT-IIoT2024, Deep learning, extraction, Feature extraction, Features extraction, Graph Neural Networks, Graphic methods, IIoT, Industrial infrastructure, Industrial internet of thing, Learning systems, Message passing, Network architecture, Network frameworks, Network security, Relational learning, Threat detection
@inproceedings{merzoukiGraphNeuralNetwork2025,
title = {Graph Neural Network Framework for Advanced Persistent Threat Detection in IIoT Environments},
author = {K. Merzouki and Y. Hadi and H. Elghazi and H. Moudoud and Z. A. El Houda},
editor = {El Bouanani F. and Ayoub F.},
url = {https://www.scopus.com/pages/publications/105032074689?origin=resultslist},
doi = {10.1109/CommNet68224.2025.11288886},
isbn = {979-833155781-2 (ISBN)},
year = {2025},
date = {2025-01-01},
booktitle = {Int. Conf. Adv. Commun. Technol. Netw., CommNet - Proc.},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {The increasing reliance of industrial infrastructures on the Industrial Internet of Things (IIoT) has made them more vulnerable to complex cyberattacks, especially Advanced Persistent Threats (APTs). To recognize and analyze these multi-stage incursions, we require computational models that can capture both structural and temporal connections in IIoT network architectures. This paper presents a framework based on Graph Neural Networks (GNNs) for detecting and classifying APTs in IIoT settings. We use the CICAPT-IIoT2024 dataset, which provides realistic multi-phase APT attack scenarios. The approach models system components, network communications, and process interactions as nodes and edges in a dynamic graph, allowing for relational learning and context-aware feature extraction. The GNN architecture leverages graph connectivity patterns and message-passing techniques to identify attack phases with greater accuracy and robustness. Experimental results show that this method outperforms traditional deep learning techniques and ensemble methods, particularly in early-stage anomaly detection. This paper highlights the potential of graph-based learning as an effective way to enhance IIoT infrastructure security against the changing behaviors of advanced persistent threats. © 2025 IEEE.},
note = {Journal Abbreviation: Int. Conf. Adv. Commun. Technol. Netw., CommNet - Proc.},
keywords = {Advanced persistent threat, Advanced Persistent Threats, Anomaly detection, CICAPT-IIoT2024, Deep learning, extraction, Feature extraction, Features extraction, Graph Neural Networks, Graphic methods, IIoT, Industrial infrastructure, Industrial internet of thing, Learning systems, Message passing, Network architecture, Network frameworks, Network security, Relational learning, Threat detection},
pubstate = {published},
tppubtype = {inproceedings}
}



